Untitled attachment
https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/131/590/878/553/924/original/04e9ba1d9ab88fcc.png
This September's release of CVE-2024-38014 mitigates an entire class of LPE vulnerabilities on Windows. 🎉
That is, prior to this update, a non-admin user can trigger an MSI repair operation, which might do some unsafe things with SYSTEM privileges.
After this update, such MSI files will prompt the user for admin credentials.
https://sec-consult.com/blog/detail/msi-installer-repair-to-system-a-detailed-journey/
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.